Recent moves by the Securities and Exchange Commission (SEC) is showcasing a new level of diligence when it comes to Chief Information Security Officers (CISOs) and their responsibilities. This increased pressure and attention toward CISO liability is not accidental, but a purposeful strategy, exemplified by the litigation surrounding SolarWinds.
SolarWinds—a prominent software company—has been in the spotlight due to SEC charges filed against their CISO. The underlying causes of these charges and the subsequent litigation put a keen focus on the extensive responsibilities and potential liabilities that CISOs carry within any organization.
Depending on the outcome of the SolarWinds situation, legal professionals should anticipate a potential period of regulatory adjustment. This will inevitably have a profound impact on how corporations conduct business, specifically in areas concerning information security.
So, what can companies do to protect their CISOs, especially with this increasing scrutiny from the SEC? It’s clear that risk mitigation strategies need to be reconsidered and more robust insurance policies considered.
Firstly, investing in an advanced and thorough education regarding the present-day risks and duties that CISOs face would be beneficial. An understanding of the landscape would develop a strong foundation to understand any possible litigation process. Secondly, the consideration of robust insurance plans that protect against executive liability is paramount.
In conclusion, the era of intense scrutiny for CISOs is here. The litigation landscape is evolving fast, and being prepared is crucial. Corporations and legal professionals must stay informed about these developments and respond accordingly to mitigate risks and protect those at the helm of their information security.